US2002061107A1PendingUtilityA1

Methods and apparatus for implementing a cryptography engine

Priority: Sep 25, 2000Filed: Sep 6, 2001Published: May 23, 2002
Est. expirySep 25, 2020(expired)· nominal 20-yr term from priority
G06F 7/49936H04L 2209/24H04L 2209/125G06F 7/722H04L 63/0428H04L 9/0625H04L 9/12
22
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Methods and apparatus are provided for implementing a cryptography engine for cryptography processing. A variety of techniques are described. A cryptography engine such as a DES engine running at a clock frequency higher than that of surrounding logic can be synchronized with the surrounding logic using a frequency synchronizer. Sbox logic output can be more efficiently determined by intelligently arranging Sbox input.

Claims

exact text as granted — not AI-modified
What is claimed is:  
     
         1 . A cryptography engine for performing cryptographic operations on a data block, the cryptography engine comprising: 
 expansion logic configured to expand a first bit sequence into a second bit sequence by moving and duplicating selected bits in the first bit sequence to form a second bit sequence having a length greater than the length of the first bit sequence, the resulting bit sequence having duplicated bits and nonduplicated bits corresponding to a portion of the data block;    Sbox logic coupled to the output of expansion logic, wherein nonduplicated bits are selected and provided as inputs to a critical path of the Sbox logic to perform cryptographic operations on the portion of the data block.    
     
     
         2 . The cryptography engine of  claim 1 , wherein the Sbox logic comprises a plurality of stages.  
     
     
         3 . The cryptography engine of  claim 2 , wherein nonduplicated bits are selected as inputs to a first stage of the Sbox logic.  
     
     
         4 . The cryptography engine of  claim 3 , wherein the first stage of the Sbox logic performs a table lookup.  
     
     
         5 . The cryptography engine of  claim 2 , wherein the first stage of the Sbox logic is a multiplexer.  
     
     
         6 . The cryptography engine of  claim 5 , wherein the second stage of the Sbox logic is a multiplexer.  
     
     
         7 . The cryptography engine of  claim 6 , wherein duplicated bits are provided as inputs to the second stage of the Sbox logic.  
     
     
         8 . The cryptography engine of  claim 1 , wherein bits  3  and  4  are provided to the critical path of the Sbox logic.  
     
     
         9 . The cryptography engine of  claim 1 , wherein the first bit sequence is 6 bits in length.  
     
     
         10 . The cryptography engine of  claim 1 , wherein the second bit sequence is 4 bits in length.  
     
     
         11 . A method for performing cryptographic operations on a data block, the method comprising: 
 providing a first bit sequence to expansion circuitry, the expansion circuitry configured to move and duplicate bits in the first bit sequence to output a second bit sequence having a length greater than the length of the first bit sequence;    identifying nonduplicated bits output by the expansion circuitry;    providing nonduplicated bits to a first stage of Sbox circuitry;    identifying duplicated bits output by the expansion circuitry, wherein duplicated bits correspond to bits in a first bit sequence that are replicated to produce a second bit sequence;    providing duplicated bits and the output of the first stage of Sbox circuitry to a second stage of Sbox circuitry, wherein duplicated bits are provided to the second stage of Sbox circuitry after nonduplicated bits are provided to the first stage of Sbox circuitry.    
     
     
         12 . The method of  claim 11 , wherein the Sbox circuitry comprises three stages.  
     
     
         13 . The method of  claim 12 , wherein the first stage of Sbox circuitry is a case statement.  
     
     
         14 . The method of  claim 12 , wherein the first stage of Sbox circuitry performs a table lookup.  
     
     
         15 . The method of  claim 12 , wherein the first stage of Sbox circuitry is a multiplexer.  
     
     
         16 . The method of  claim 15 , wherein the second stage of Sbox circuitry is a multiplexer.  
     
     
         17 . The method of  claim 11 , wherein bits  3  and  4  of a 6 bit block are provided to the first stage of Sbox circuitry.  
     
     
         18 . A cryptography accelerator for performing cryptographic operations on a data block, the cryptography accelerator comprising: 
 means for providing a first bit sequence to expansion circuitry, the expansion circuitry configured to move and duplicate bits in the first bit sequence to output a second bit sequence having a length greater than the length of the first bit sequence;    means for identifying nonduplicated bits output by the expansion circuitry;    means for providing nonduplicated bits to a first stage of Sbox circuitry;    means for identifying duplicated bits output by the expansion circuitry, wherein duplicated bits correspond to bits in a first bit sequence that are replicated to produce a second bit sequence;    means for providing duplicated bits and the output of the first stage of Sbox circuitry to a second stage of Sbox circuitry, wherein duplicated bits are provided to the second stage of Sbox circuitry after nonduplicated bits are provided to the first stage of Sbox circuitry.    
     
     
         19 . The cryptography accelerator of  claim 18 , wherein the Sbox circuitry comprises three stages.  
     
     
         20 . The cryptography accelerator of  claim 19 , wherein the first stage of Sbox circuitry is a case statement.  
     
     
         21 . The cryptography accelerator of  claim 19 , wherein the first stage of Sbox circuitry performs a table lookup.  
     
     
         22 . The cryptography accelerator of  claim 19 , wherein the first stage of Sbox circuitry is a multiplexer.  
     
     
         23 . The cryptography accelerator of  claim 22 , wherein the second stage of Sbox circuitry is a multiplexer.  
     
     
         24 . The cryptography accelerator of  claim 18 , wherein bits  3  and  4  of a 6 bit block are provided to the first stage of Sbox circuitry.  
     
     
         25 . A cryptography accelerator for performing cryptography operations, the cryptography accelerator comprising: 
 a DES engine;    a frequency synchronizer coupled to the DES engine;    surrounding logic coupled to the DES engine and the frequency synchronizer, wherein the DES engine operates at a first clock rate and the surrounding logic operates at a second clock rate different from the first clock rate.    
     
     
         26 . The cryptography accelerator of  claim 25 , wherein the first clock rate is faster than the second clock rate.  
     
     
         27 . The cryptography accelerator of  claim 25 , wherein the frequency synchronizer signals the DES engine to begin performing cryptography operations.  
     
     
         28 . The cryptography accelerator of  claim 25 , wherein the frequency synchronizer signals the surrounding logic to read processed data from the DES engine after cryptography operations are performed.  
     
     
         29 . The cryptography accelerator of  claim 25 , wherein the frequency synchronizer uses a reference clock associated with the surrounding logic to synchronize a 1×clock and a higher multiple clock associated with the DES engine.  
     
     
         30 . The cryptography accelerator of  claim 25 , wherein the negative edge of the 1×clock is used to catch a start signal associated with the reference clock to allow consideration of skew.  
     
     
         31 . The cryptography accelerator of  claim 25 , wherein the second positive edge of the 3×clock is used to catch the start signal

Join the waitlist — get patent alerts

Track US2002061107A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.